CVE-2025-30198

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1s_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1s_pro:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1_pro_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_pro_omni:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_omni:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1s_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1s_pro:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1_turbo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_turbo:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1s_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1s_pro:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t10_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10_omni:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t10_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10_plus:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t10_turbo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10_turbo:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t20_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t20_omni:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t20_pro_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t20_pro_plus:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t20_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t20_pro:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t30_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t30_omni:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t30s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t30s:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-09-05 18:15

Updated : 2025-09-23 17:11


NVD link : CVE-2025-30198

Mitre link : CVE-2025-30198

CVE.ORG link : CVE-2025-30198


JSON object : View

Products Affected

ecovacs

  • deebot_t20_omni
  • deebot_t30s_firmware
  • deebot_t10
  • deebot_t30_omni
  • deebot_t30s
  • deebot_t20_pro_firmware
  • deebot_t20_omni_firmware
  • deebot_t10_turbo
  • deebot_x1_pro_omni
  • deebot_x1s_pro
  • deebot_t10_plus
  • deebot_x1_omni_firmware
  • deebot_t20_pro
  • deebot_t10_omni_firmware
  • deebot_t30_omni_firmware
  • deebot_x1s_pro_firmware
  • deebot_t10_omni
  • deebot_t20_pro_plus_firmware
  • deebot_t10_plus_firmware
  • deebot_x1_turbo
  • deebot_x1_pro_omni_firmware
  • deebot_t20_pro_plus
  • deebot_t10_firmware
  • deebot_x1_turbo_firmware
  • deebot_t10_turbo_firmware
  • deebot_x1_omni
CWE
CWE-321

Use of Hard-coded Cryptographic Key

CWE-798

Use of Hard-coded Credentials